|
267471
|
4.3 |
MEDIUM
Network
|
cybozu
|
mailwise
|
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.
|
CWE-200
Information Exposure
|
CVE-2016-4844
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267472
|
6.5 |
MEDIUM
Network
|
cybozu
|
mailwise
|
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.
|
CWE-200
Information Exposure
|
CVE-2016-4843
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267473
|
4.3 |
MEDIUM
Network
|
cybozu
|
mailwise
|
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.
|
CWE-200
Information Exposure
|
CVE-2016-4842
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267474
|
5.9 |
MEDIUM
Network
|
dmm
|
dmmfx_demo_trade gaitamejapan_fx_trade dmmfx_trade
|
DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2016-4818
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267475
|
6.1 |
MEDIUM
Network
|
geeklog_project
|
geeklog
|
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE edition 2.1.1 allow remote attackers to inject arbitrary web script or HTML by leveraging use of the COM_getCurrentURL function in…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4849
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267476
|
6.1 |
MEDIUM
Network
|
ossec
|
web_ui
|
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4847
|
2024-11-21 11:53 |
2017-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267477
|
3.5 |
LOW
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.
|
CWE-284
Improper Access Control
|
CVE-2016-4874
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267478
|
4.3 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
|
CWE-275
Permission Issues
|
CVE-2016-4873
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267479
|
4.3 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.
|
CWE-200
Information Exposure
|
CVE-2016-4872
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267480
|
6.5 |
MEDIUM
Network
|
cybozu
|
office
|
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.
|
CWE-399
Resource Management Errors
|
CVE-2016-4871
|
2024-11-21 11:53 |
2017-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|